Skip to content
Pylon Digital

AI security & privacy · Guide

AI acceptable use policy: what it must cover for law and accounting firms

An AI acceptable use policy tells staff which AI tools they may use, what information can go into them, how outputs are checked and who is accountable. Australian law and accounting firms also need it to deal with client confidentiality and privacy obligations. This guide explains each clause, and our free template supplies the wording.

Published
Last reviewed
Reading time
7 min read

Why does a firm need an AI acceptable use policy?

A firm needs one because staff are already making AI decisions every day, and without a policy each person makes them alone. A written policy turns those private judgements into firm rules that partners have agreed, that new staff can learn, and that the firm can point to when a client or regulator asks how AI is used.

Regulators expect it. The OAIC’s guidance on privacy and commercially available AI products says organisations should establish policies and procedures for AI use and make sure staff are trained to monitor for inaccurate outputs. For law practices, the statement on the use of AI in Australian legal practice, issued in December 2024 by the Law Society of NSW, the Legal Practice Board of WA and the Victorian Legal Services Board and Commissioner, expects clear, risk-based policies covering which tools are permitted and how junior and support staff are supervised.

A policy is also the constructive answer to shadow AI in professional firms. It tells staff what they can use, not only what they cannot.

What clauses must the policy include?

Ten clauses cover what a 10–100 person law or accounting firm needs. The table summarises them; the sections below explain what each clause should say and where law and accounting firms differ.

ClauseWhat it settles
1. ScopeWho and what the policy covers
2. Approved toolsThe named tools and accounts staff may use
3. Information rulesWhat information may go into which tool
4. Checking outputsWho reviews AI output, and how
5. Client transparency and billingWhat clients are told and how AI-assisted work is billed
6. PrivacyHow the Australian Privacy Principles apply
7. Accounts and securitySign-in, MFA and app permissions
8. New tools and featuresHow staff ask for a new tool or AI feature
9. IncidentsWhat to do when something goes wrong
10. Training, supervision and reviewWho is trained, who supervises, when the policy is reviewed

1. Scope

The policy applies to partners, employees, contractors and anyone else doing firm work, on firm devices and personal ones. Define “AI tool” broadly: chat assistants, AI features inside existing software, browser extensions, meeting note-takers and transcription services. A narrow definition leaves the riskiest tools outside the policy.

2. Approved tools

List each approved tool by name, plan and purpose, for example “ChatGPT Business, firm workspace, drafting and summarising non-client material”. State plainly that personal accounts, free tiers and consumer apps may not be used for firm work, because the firm cannot control their data settings or retrieve anything when someone leaves. Keep the list in a register the practice manager can update without redrafting the policy, and make sure each tool is configured to match; our checklist to set up ChatGPT Business securely shows what that involves for one tool.

3. Information rules

This is the clause that matters most. Sort information into a small number of classes, such as public, internal, client confidential and prohibited, and say which approved tool each class may go into. The OAIC recommends, as best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots. The legal regulators’ statement says lawyers cannot safely enter confidential, sensitive or privileged client information into public AI chatbots such as ChatGPT, and that commercial tools need their contractual terms reviewed carefully before client information goes in.

Name the categories staff actually handle, so nobody has to interpret a general rule under deadline:

  • Law firms: privileged communications, material covered by suppression or non-publication orders, trust account records, and documents obtained under subpoena or discovery.
  • Accounting firms: tax file numbers, bank and ATO account details, payroll data and clients’ personal financial information.

4. Checking outputs

AI tools produce fluent text that can be wrong, including invented citations, figures and case names. This is called hallucination. The clause should require a named person to review every AI-assisted output before it is relied on or leaves the firm, and make that reviewer answerable for it as if they had written it. The OAIC links this to APP 10, the obligation to take reasonable steps to keep personal information accurate, which includes human oversight of AI outputs. The legal regulators add that lawyers cannot rely on AI output as a substitute for their own judgement. Litigation teams should also check court rules; the Supreme Court of NSW, for example, has issued Practice Note SC Gen 23 on the use of generative AI.

5. Client transparency and billing

Say when and how clients are told that AI was used. A simple approach is a sentence in the engagement letter describing the approved tools and how client information is protected, plus a file note when AI materially contributes to advice. For law practices, the regulators’ statement expects lawyers to record and disclose to clients, where appropriate, when and how AI was used in a matter, and to bill only for work actually done. Accounting firms should apply the same test to time recorded against jobs in Xero Practice Manager or their practice management system.

6. Privacy

The Privacy Act applies to organisations with annual turnover above $3 million and some others, so most firms in this size range need to check whether they are covered (OAIC: the Privacy Act). Where it applies, the OAIC’s guidance points to APP 6 (using personal information only for the purpose it was collected, unless an exception applies), APP 8 (cross-border disclosure, relevant where an AI provider stores data overseas), APP 3 (personal information that AI generates counts as a collection) and APP 1 (the privacy policy should explain the firm’s use of AI). The clause should name the firm’s privacy officer and point staff to our plain-English guide to AI and the Australian Privacy Principles.

7. Accounts and security

Staff sign in to approved tools with their work account through single sign-on, with multi-factor authentication, and never share logins. Staff must not connect an AI tool to firm email, SharePoint, Google Drive or the practice management system, or approve an app’s request for access to their mailbox, without IT approval. That rule matters because, by default, Microsoft Entra ID lets users consent to apps that request access to their own mailbox.

8. New tools and features

Give staff a simple route to ask for a tool: a short request to the practice manager, reviewed before approval. The OAIC expects due diligence before an organisation adopts an AI product, including how it handles data, what security risks it carries and whether the developer or third parties can access the information. Cover AI features too, not just new products: a vendor update can switch on an AI feature inside software you already use and send data to a new provider.

9. Incidents

Tell staff exactly what to do if client information goes into an unapproved tool, or an AI output causes an error: report it to a named person the same day, with no penalty for honest reporting. The firm then records what happened, removes the data where it can, and assesses whether it is an eligible data breach under the Notifiable Data Breaches scheme, which requires notification when a breach is likely to result in serious harm.

10. Training, supervision and review

Everyone completes a short induction on the policy before getting access to an approved tool, and signs an acknowledgement. Supervising partners and solicitors are responsible for how the people they supervise use AI. Name who reviews the policy and when, and record the version and approval date on the document.

How do you roll the policy out?

Roll it out in five steps: find out what staff use now, choose and configure approved tools, adapt the wording, get partner sign-off, and train everyone before access is switched on.

  1. Survey current use without blame. Ask which tools staff use, for which tasks and with what kind of information. The task list tells you what the approved tools must do.
  2. Choose and configure approved tools. Set up single sign-on, MFA, apps and data controls before anyone logs in.
  3. Adapt the wording. Fill in the approved-tools register, the information classes for your practice and the named roles.
  4. Get partner sign-off. Record the version, the approval date and the accountable partner.
  5. Train, then switch on access. Collect acknowledgements at the induction session, and give access to approved tools only after that.

Example: a 40-person law firm on LEAP

Illustrative scenario: a paralegal at a 40-person law firm wants to summarise a 300-page discovery bundle. Under the firm’s policy, the bundle is client confidential, so it cannot go into the firm’s ChatGPT Business workspace, which partners approved for non-client material only. The paralegal uses the firm’s approved private document assistant instead. The supervising solicitor checks the summary against the source documents, and a file note in LEAP records that AI was used and who reviewed the output. The policy made each decision in advance, so nobody had to improvise.

Where can you get the template?

Our free AI acceptable use policy template is on the resources page. The download asks for your name, firm and email; this guide stays open to everyone. Use it as a starting point, adapt it to your practice, and have your lawyer review the final version, particularly the privacy and incident clauses. Pylon Digital’s AI Setup service includes the usage policy and staff onboarding alongside configuring the tools, so the policy and the settings match.

This is general information, not legal advice.

Questions

Frequently asked questions

Do regulators expect firms to have an AI policy?

Yes. The OAIC's guidance on commercially available AI products says organisations should establish policies and procedures for using AI and train staff to watch for inaccurate outputs. The December 2024 statement from the NSW, WA and Victorian legal regulators expects law practices to have clear, risk-based policies on which AI tools are permitted and how junior staff are supervised.

Should our AI policy ban ChatGPT?

Usually not outright. A ban with no approved alternative tends to move AI use onto personal phones and accounts, where the firm has no visibility at all. A better rule is that personal and free accounts are banned for firm work, while a named, firm-managed tool is approved for defined tasks. That keeps the useful work and brings it under the firm's controls.

Who should own the AI acceptable use policy?

A named partner should be accountable, with the practice manager running it day to day. The partner signs off changes and decides grey-area requests. The practice manager keeps the approved-tools register, handles new tool requests and runs induction. In law firms, supervising solicitors stay responsible for how their juniors use AI on the matters they supervise.

How often should we review the policy?

Review it at least twice a year, and whenever an approved tool changes materially. AI vendors change plan names, settings and terms often; OpenAI renamed ChatGPT Team to ChatGPT Business in August 2025, for example. Each review should check the approved-tools register, compare the information rules with each tool's current terms, and look at incidents and requests since the last review.

Does the policy need to cover personal devices?

Yes, because a personal phone is the easiest way around a policy that only covers firm devices. The policy should apply to firm work wherever it happens. A clear rule is that no client information goes into an AI app on a personal device unless it is an approved tool, signed in with the staff member's work account.

Is the AI acceptable use policy template free?

Yes. The template is free on our resources page; the download asks for your name, firm and email. This article stays open to everyone. Treat the template as a starting point: fill in your approved tools and named roles, match the information rules to your practice, and have your lawyer review the adapted version before partners adopt it.

Secure by design. Set up correctly. Fully managed.

Talk to us before you commit to anything

Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.

Book a free 45-minute discovery call